CVE-2018-10393: High severity libvorbisfile vulnerability
A flaw was found in libvorbis 1.3.6. The barknoisehybridmp function in psy.c file in Xiph.Org has a stack-based buffer over-read which allows remote attackers to cause a denial of service via a crafted file.
References: https://gitlab.xiph.org/xiph/vorbis/issues/2334
Other sources
barknoisehybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10393?
CVE-2018-10393 is classified as a denial of service vulnerability due to a stack-based buffer over-read.
How do I fix CVE-2018-10393?
To fix CVE-2018-10393, update libvorbis to version 1.3.7 or later.
Which versions of libvorbis are affected by CVE-2018-10393?
CVE-2018-10393 affects libvorbis version 1.3.6.
What software is impacted by CVE-2018-10393?
CVE-2018-10393 impacts libvorbis and certain distributions of Debian and Red Hat Enterprise Linux.
Can CVE-2018-10393 be exploited remotely?
Yes, CVE-2018-10393 can be exploited remotely through the use of crafted files.